Ticket #78 (closed Bug: fixed)

Opened 18 months ago

Last modified 8 months ago

ASP.Net connector still accepts the user files path from the URL

Reported by: FredCK Owned by: FredCK
Priority: High Milestone: FCKeditor.Net 2.5
Component: Server : ASP.Net Version:
Keywords: Cc:

Description

The "ServerPath" URL parameter can still be used to set the server path for the user files folder.

We have been pressed to leave this option in the past, but this is a huge security risk. So, let's remove it. Those users who still prefer the URL will have to accept this option and understand that this is a important security limit.

Change History

Changed 18 months ago by FredCK

  • milestone changed from FCKeditor 2.5 to FCKeditor.Net 2.3

Changed 8 months ago by fredck

Fixed with [1168].

Changed 8 months ago by fredck

  • status changed from new to closed
  • resolution set to fixed
Note: See TracTickets for help on using tickets.